安全审计方法论技能包 + plugin_vet 供应链门禁:八个 agent 技能(密钥扫描、依赖审计、供应链评审、提示注入审查、审计总编排、威胁建模、漏洞情报、事件响应),中英双版本,附 npm provider 包一键挂载并注册自动化 plugin_vet 安装前扫描。
安装
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:PerryLink/dsh-skill-pack-security
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
dsh-skill-pack-security
- 1024 商店渠道:先
npm i -g dsh1024,再dsh1024 plugin --profile web add dsh-skill-pack-security(计入 deepseek1024.com 安装排行)。
面向 DeepSeek Harness 的八个安全审计技能 + 一个自动化插件供应链门禁。
技能教审计方法论;plugin_vet 工具执行安装前扫描——许可证 / SBOM / commit 锁定 / 恶意模式 / 五维风险卡片。
English · 简体中文 · Español · Português · हिन्दी
Compatibility
| 维度 | 状态 |
|---|---|
| Harness | DeepSeek Harness dsh-v0.1.7-rc.2(GitHub tag,已于 2026-09-24 核验:完整门禁链 + profile 安装冒烟)。npm 依赖线:@deepseek-ai/dsh 0.1.5-rc.2(peers `>=0.1.2-rc.1 <0.2.0 |
| Node | ^22.19.0 || >=24.0.0(DeepSeek Harness 运行时) |
| 平台 | 任意(技能是内容;provider 是 host 插件) |
| 模型 | 任意(技能经 skill 工具按需加载;plugin_vet 是确定性的) |
What you get
dsh-skill-pack-security 是面向 DeepSeek Harness 的技能包 + 供应链门禁。它把 8 套安全方法论做成 SKILL.md 技能(模型在会话目录中发现它们,用 skill 工具按需加载),并附自动化安装前扫描器 plugin_vet。技能教方法论,插件执行静态检查。
- 八个技能、双语双套 —— 每个技能以相同名称与元数据提供
skills/(中文)与skills-en/(英文)两个版本;每个根目录只装一种语言。 plugin_vet门禁 —— 由可选provider/插件注册到ctx.tools的零依赖扫描器(许可证 / SBOM / commit 锁定 / 恶意模式 / 数据责任审查 / 五维风险卡片)。- 发现引用技能 —— 每个发现指向对应技能章节(如
supply-chain-review §1),agent 可继续人工审计。 - 可被模型执行 —— 每个技能步骤都是真实命令(
gitleaks、trivy、pnpm audit、npm view、git …),附预期输出样例与退出码判据。
Why skills, not tools?
| 形态 | 做什么 | 做不到什么 |
|---|---|---|
| 工具型插件(如扫描器) | 执行扫描、返回发现 | 解读告警、误报分级、写脱敏报告 |
| 协议层 | 约束某个协议 | 跨仓库、跨 agent 泛化 |
| 技能包(本仓库) | 传授方法论:分级、报告、修复排序——并通过 plugin_vet 自动执行安装前静态检查 |
端到端取代人工审计 |
与工具型安全插件同装时两者互补:工具负责跑扫描,技能负责解读、分级与报告。本包现在两种形态兼有:技能教方法论,plugin_vet 自动跑机械性的静态子集,每个发现都指回技能继续深挖。
Claude Code 生态 3000+ 技能已经证明这种形态的分发价值。DSH 的 SKILL.md frontmatter(name/description/whenToUse)与 CC 技能格式兼容;本包只用公共子集,内容全部原创。
The eight skills
| 技能 | 用途 | 何时用 |
|---|---|---|
security-audit |
五阶段审计流程:范围→资产清单→风险分级→验证→报告模板 | 整体审计、出报告、规划步骤 |
secret-scan |
凭据审计:gitleaks/trivy 用法、误报分级、脱敏报告、修复排序 | 密钥扫描、告警定真伪、泄露报告 |
dependency-audit |
供应链审计:pnpm/npm audit 解读、license、投毒风险、锁文件漂移 | 依赖盘点、audit 报告解读 |
supply-chain-review |
PR/新依赖快速评审:危险 install 脚本、typosquat、可复现构建 | 评审引入新依赖的 PR |
prompt-injection-review |
agent 项目注入面审查:AGENTS.md、技能、工具描述、MCP、网页 | 审查模型上下文注入面 |
threat-model |
设计期威胁建模:信任边界、STRIDE 表、攻击树、缓解 | 新功能建模、设计阶段安全评审 |
vuln-intel |
漏洞情报:NVD/CISA-KEV/GHSA/OSV 检索与判定 | 拿到 CVE/GHSA 编号后查影响与利用 |
incident-response |
agent 环境事件响应:控制→取证→恢复→复盘 | DSH/agent 环境出现疑似安全事件 |
每个技能主文件 ≤ 300 行(渐进披露,细节在 references/)。
plugin_vet — the automated pre-install gate
plugin_vet 是本包的自动化补充:由 provider/ 插件注册到 ctx.tools 的零依赖扫描器。传入 GitHub owner/repo 或本地包路径即可——一次性下载 tarball(遵守超时与 AbortSignal)、在预算上限内扫描,并返回渲染卡片。
- 许可证扫描 —— 定位 LICENSE 文件与
license字段;NOASSERTION/UNKNOWN/SEE LICENSE IN <file>、文件缺失或字段缺失都会被标出;常见 SPDX 标识可识别。 - SBOM —— 从锁文件(pnpm/npm/yarn)提取带版本的依赖树。
- commit 锁定 —— 安装清单 ref 与 workflow action 必须是不可变的 40 位 commit SHA;
@tag/分支 ref 会被标记为可变。 - 恶意模式 —— 生命周期脚本(
preinstall/install/postinstall)、网络回传域名、发布代码中的混淆/编码载荷。 - 数据责任审查 —— 策略扫描三维的确定性规则版:敏感 seam(
agent/pre-step、tools/pre-execute、session/event等)上的无门控监听、README 未披露出站端点、描述-行为关键词覆盖率、随包文本中的指令覆盖类注入载荷(技能/文档/提示词/测试)。每条发现都指向prompt-injection-review供人工深审;可用vet.dataResponsibility: false按部署关闭。模型辅助审查阶段为已文档化的后续升级。 - 五维风险报告 —— 许可证 / 来源 / 依赖 / 构建脚本 / 维护状态,各 0–100 分,汇总为整体判定:PASS、WARN 或 FAIL。
安装前门禁。 判定结果进入安装门禁——gate.policy: warn(默认,不阻断)在 FAIL 时打印警告;gate.policy: deny 直接阻断安装:
- id: skill-pack-security
name: '@perrylink/dsh-skill-pack-security-provider'
config:
language: en
vet:
gate:
policy: deny # 阻断 plugin_vet 不过的安装
与 dsh-plugin-check 互补。 官方插件校验器的 36 项检测验证插件的契约与质量(配置 Schema、effect 注册、工具 JSON 形态);plugin_vet 验证插件的来源供应链是否可信。两者都跑:
dsh-plugin-check(36 项检测) |
plugin_vet(本仓库) |
|
|---|---|---|
| 回答的问题 | 这个插件是否结构良好、符合契约? | 这个包安装是否安全? |
| 检查对象 | 插件代码、Schema、注册、工具契约 | LICENSE、锁文件、安装 ref/action、生命周期脚本、回传/混淆、维护状态、数据责任(监听作用域、遥测披露、描述-行为、嵌入式注入载荷) |
| 判定 | 逐项 pass/fail | PASS / WARN / FAIL + 门禁 |
| 时机 | 插件开发或评审时 | dsh plugin add 前、PR 评审、CI 供应链门禁 |
| 阻断 | CI 门禁(有违规即非零退出) | 可配置:warn(默认)或 deny |
Quick start
# 1. 把 bundle 安装进 profile
dsh plugin --profile web add "github:PerryLink/dsh-skill-pack-security#main"
# 或从 npm(发布版本)
dsh plugin --profile web add @perrylink/dsh-skill-pack-security-provider
# 2. 重启并校验该行
dsh --profile web --dump-config | grep -A3 'id: skill-pack-security'
Install & uninstall
- git 通道(最新
main):dsh plugin --profile web add "github:PerryLink/dsh-skill-pack-security#main"—— 挂载 provider bundle;prepack把双语言版嵌入 tarball。 - npm 通道(发布版本):
dsh plugin --profile web add @perrylink/dsh-skill-pack-security-provider。 - tarball 通道:在
provider/里pnpm pack,再dsh plugin --profile web add ./@perrylink-dsh-skill-pack-security-provider-<version>.tgz。 - 卸载:
dsh plugin --profile web remove @perrylink/dsh-skill-pack-security-provider(或删除该行;纯技能副本用安装器的-Uninstall/--uninstall删除)。
Installing the skills by hand
DSH 本地技能提供方按 rank 扫描四个根目录(同层内重名时低 rank 胜出):
| Rank | 根目录 | 适用范围 |
|---|---|---|
| 100 | <项目根>/.dsh/skills |
项目级、随仓库走 |
| 200 | <项目根>/.agents/skills |
项目级、跨 agent 共享目录 |
| 400 | <dshHome>/skills($DSH_HOME 或 ~/.dsh) |
用户级、DSH 专用 |
| 500 | <agentsHome>/skills($DSH_AGENTS_HOME 或 ~/.agents) |
用户级、跨 agent 共享 |
Rank 链(同层内重名低者胜):project-dsh 100 < project-agents 200 < custom 300 < user-dsh 400 < user-agents 500。custom 300 是插件注册层(如本包可选的 provider/),不是磁盘根目录。
./scripts/install.ps1 -Target user-agents -Language zh # Target: project-dsh | project-agents | user-dsh | user-agents;Language: zh(默认)| en
bash ./scripts/install.sh --target user-agents --language en
What's inside
| 路径 | 内容 |
|---|---|
skills/<name>/SKILL.md |
8 个技能(中文版);frontmatter 逐条符合官方 dsh-skill-filesystem 契约 |
skills-en/<name>/SKILL.md |
8 个技能(英文版);名称与元数据与中文版一致 |
skills/<name>/references/ |
渐进披露细节:命令矩阵、分级表、模板 |
scripts/install.ps1 |
Windows 一键安装(四种根目录、两种语言版);记录清单,支持 -Uninstall/-DryRun/-Force |
scripts/install.sh |
POSIX 等价安装器(--uninstall/--dry-run/--force) |
provider/ |
npm 可安装的 provider bundle(声明 dsh.bundle;prepack 把双语言版嵌入 pack/;language: zh|en);经 ctx.effect() 注册技能提供方与 plugin_vet 门禁工具,skillsDir 配错响亮失败 |
provider/src/vet/ |
零依赖 plugin_vet 扫描引擎(许可证 / SBOM / commit 锁定 / 恶意模式 / 风险报告) |
package.json |
根 bundle manifest:声明 dsh.bundle.patch(→ provider/cordis.patch.yml)与 dshWorkshop intake 事实 |
verify/verify-skill-pack.mts |
官方解析器 + 真实 skill 工具 + 真实工具运行时 headless 校验——双语共 25 项检查 |
VERSION |
版本单一来源;每个 SKILL.md 的 metadata.version 与 provider/package.json 必须与其一致(CI 强制) |
docs/ |
生态冲突检查、发布清单、改进计划与 plugin_vet 演示 |
CHANGELOG.md / SECURITY.md / CONTRIBUTING.md |
发布历史、漏洞报告政策、贡献与校验规则 |
.github/workflows/verify.yml |
CI:25 项校验 + 安装器演练 + provider 独立构建/打包冒烟(Ubuntu 与 Windows) |
.github/dependabot.yml |
provider 与 GitHub Actions 的每周依赖更新 |
LICENSE |
Apache License 2.0 |
THIRD_PARTY_NOTICES.md |
第三方立场:零依赖引擎、已评估未移植的资产、peer 依赖许可 |
Configuration
所有可调项都是 Schemastery Config 字段(可从 cordis.yml 覆盖)。provider/cordis.patch.yml 逐键内联注释。
| 键 | 默认值 | 含义 |
|---|---|---|
language |
zh |
发布的语言版:中文 skills/ 或英文 skills-en/;设置 skillsDir 后忽略 |
watch |
false |
是否监听打包技能目录(内容静态,故默认关闭) |
skillsDir |
(未设置) | 显式技能根目录;覆盖 language 推导的默认值,须含 <skill>/SKILL.md 技能 |
vet.enable |
true |
注册 plugin_vet 门禁工具 |
vet.timeoutMs |
15000 |
tarball 下载超时(毫秒) |
vet.maxFiles |
800 |
扫描文件数上限 |
vet.maxFileBytes |
262144 |
单文件字节上限 |
vet.maxExtractBytes |
67108864 |
解压字节上限 |
vet.maxDepNodes |
600 |
依赖树节点上限 |
vet.maxFindingsPerCheck |
12 |
每项检查的发现数上限 |
vet.dataResponsibility |
true |
运行数据责任审查(可按部署禁用) |
vet.externalScanners |
true |
当 osv-scanner/npm audit CLI 存在时编排它们;false 强制使用内置自计算依赖扫描 |
vet.userAgent |
dsh-skill-pack-security/2.2.17 (+https://github.com/PerryLink/dsh-skill-pack-security) |
下载用的 user-agent |
vet.gate.policy |
warn |
安装门禁:warn(不阻断)或 deny(FAIL 时阻断) |
Tools & surfaces
| 表面 | 类型 | 说明 |
|---|---|---|
plugin_vet |
tool | 安装前供应链扫描(许可证 / SBOM / commit 锁定 / 恶意 / 风险卡片);发现引用技能章节 |
skill-pack-security |
skill provider | 把本包的 skills/ 或 skills-en/ 版本注册到 ctx.skills |
八个 SKILL.md 技能 |
skills | 审计方法论,两个语言版 |
| 安装门禁 | gate | vet.gate.policy: warn | deny 决定安装是否放行 |
Permissions & data
- 权限:
dshWorkshopmanifest 声明files:read与network:fetch。 - 数据:
plugin_vet一次性下载 tarball(遵守超时与AbortSignal),报告会打码密钥形态文本;插件不注入任何 prompt 段。
Security boundaries
- 零依赖引擎。
plugin_vet只用node:内置与相对导入。 - 窄范围安装前门禁。 不是通用安全审计工具——刻意与扫描器插件、官方
dsh-plugin-check契约校验器互补。 - 默认不阻断。 安装门禁默认为
warn,除非显式选择deny。 - 内容原创。 与 Claude Code 技能格式兼容,但不复制 CC 技能内容、不设技能市场。
- 引擎原创、未移植第三方资产。 许可证扫描与恶意模式检查为原创零依赖实现;GPL-Radar / LLM-detective / Sus-PY 资产经评估未移植(未找到可核实许可证的公开源码)——见
THIRD_PARTY_NOTICES.md。
Verification
verify/verify-skill-pack.mts 从本机 deepseek-harness checkout 导入官方 dsh-skill-filesystem 解析器、真实 skill 工具与真实工具运行时,对两个语言版实测 25 项检查:
- 目录结构:两个语言版齐备、各 8 个 bundle、无多余平铺 md、frontmatter
name与目录名一致、≤ 300 行、references/已接线、metadata.version与VERSION文件同步 - 与官方
.agents/skills/技能(运行时从 checkout 推导)及已知社区技能包零重名 3–6. 每个语言版(中文skills/、英文skills-en/):官方 provider 发现全部 8 个技能、ctx.skills.get()加载全部正文、真实skill工具返回<skill_content>(未知名/非法名被拒绝)、会话目录只含name+description——whenToUse不进入模型目录(官方设计) - 13 个坏 frontmatter 用例逐条验证官方 fail-closed 规则(缺字段、驼峰遗留键、非布尔值、非 kebab 名、嵌套目录、名称不一致);平铺技能可发现,嵌套
**/SKILL.md不被发现 - 可选 provider 插件经
ctx.effect()挂载中文版与英文版、dispose 干净,并拒绝错误配置(空/不存在的skillsDir) 9–15. 自加固检查:zh↔en 结构对齐、references 接线(无悬空/孤儿文件)、provider 版本同步、文档 rank 对照官方常量、grep -E模式 POSIX 可移植、包内密钥自检、release-checklist UTF-8 安全 16–19.plugin_vet走真实工具运行时:注册到ctx.tools;合规 fixture 通过;无 license fixture 失败并引用dependency-audit §3;恶意 postinstall fixture 失败(脚本/回传/混淆,引用supply-chain-review §1);policy: deny下门禁阻断安装 - 扫描引擎零依赖(仅
node:内置与相对导入) - 报告脱敏:密钥形态文本不进入渲染输出
# 本地运行:默认自动解析包旁的 harness checkout,也可显式指定
$env:DSH_HARNESS_CHECKOUT = 'D:\deepseek-harness'
& D:\deepseek-harness\node_modules\.bin\tsx.CMD verify\verify-skill-pack.mts
# All 25 checks passed for dsh-skill-pack-security.
同样的 25 项检查由 .github/workflows/verify.yml 在 GitHub 上每次 push 自动重跑——Ubuntu 与 Windows 双平台——另有 install.sh/install.ps1 演练与 provider 独立构建/打包冒烟(断言 tarball 含双语言版与 bundle patch)。
Known limitations
- 不是完整审计工具。
plugin_vet是窄范围的安装前信任门禁,不能端到端取代人工审计。 - 仅静态扫描。 恶意模式与维护状态信号是对发布包的启发式判断,不是动态分析。
- 每根目录一个语言版。 同名技能在同一根目录内按 rank 去重,只有一个语言版进入会话目录。
Roadmap
dsh-skill-pack-data-engineering—— 数据管道、数据质量、ETL 检查清单(同模板)dsh-skill-pack-oss-collab—— PR 礼仪、issue 分类、维护者工作流dsh-skill-pack-performance—— profile 方法论、基准判定、回归清单- 本包内更多技能(保持纯技能边界):
sbom-lifecycle(SBOM 生成/老化/导入工作流)、pen-test-review(授权测试的范围界定与报告评审)、compliance-audit(ASVS/NIST-CSF 走查) - 随每次发布刷新
plugin_vet演示产物(docs/demos/run-demos.mjs),并随官方校验器新增检测保持dsh-plugin-check互补表准确
Development
pnpm --dir provider run typecheck # tsc --noEmit
pnpm --dir provider run build # tsc --noEmitOnError
pnpm --dir provider run prepack # 把两个语言版嵌入 tarball
tsx verify/verify-skill-pack.mts # 25 项 headless 校验
Benchmark
投毒样本回归集(38 个样本的逐类检出率 / 误报率 / F1,以及与 OSV/Socket 的差距)见 benchmark/RESULTS.md;用 pnpm --dir provider run build && node benchmark/run.mjs 复现(零新依赖)。
Topics
dsh, dsh-plugin, deepseek-harness, skill-pack, skills, security, security-audit, supply-chain, supply-chain-security, prompt-injection
Contributors
- @PerryLink —— 作者与维护者:双语版八个技能、安装脚本、验证套件、provider 包、CI 与文档。
PerryLink DSH Plugin Family
This project is one of the 45 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:
| Plugin | One-liner |
|---|---|
| dsh-auto-review | Second-model auto-review on the approval chain, fail-closed by default |
| dsh-autotier | Automatic strong/cheap model-tier routing with deterministic risk guards and a /tier command |
| dsh-background-agents | Durable background child agents with a Web UI sidebar, messaging and interrupt |
| dsh-budget | Cost governance for DeepSeek Harness: budgets, carbon, and latency in one panel. |
| dsh-catalog | DSH Desktop Market standard catalog source for the PerryLink family |
| dsh-cert-mcp | Read-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence |
| dsh-checkpoint-rewind | Claude Code /rewind-equivalent: snapshots, session forks, one-shot restore |
| dsh-claude-move | Migrate Claude Code sessions, memory, skills and CLAUDE.md into DSH |
| dsh-click | Cross-platform native desktop control for DeepSeek Harness — Windows first. |
| dsh-composer-history | Terminal-style input history for the web composer: arrows, Ctrl+R search |
| dsh-data-quality | Dataset quality checks and citation cross-checks (the optional numeric bridge consumed here) |
| dsh-defend | Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness. |
| dsh-doublecheck | Engineering-discipline guard: requirements grill, test gates, adversary review |
| dsh-draw | Unified static-image generation routing for DeepSeek Harness. |
| dsh-fast | Read-only performance diagnostics for DeepSeek Harness. |
| dsh-fund-research | Deterministic research reports for Chinese public mutual funds |
| dsh-github | GitHub PR/issues integration for DSH, every write gated by approval |
| dsh-industry-research | Industry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble |
| dsh-laya | Laya typed decisions (noul/choice/score) as a first-class Cordis service and model-visible tools |
| dsh-library | Local document knowledge base for DeepSeek Harness. |
| dsh-local-ai | Local-model (Ollama) integration for DeepSeek Harness. |
| dsh-lsp-actions | LSP diagnostics, formatting, completion, code actions and rename over language servers |
| dsh-mask | PII masking middleware: anonymize at the model boundary, restore at the display layer |
| dsh-mcp-panel | Read-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors |
| dsh-memento | Approval-gated cross-session memory: ctx.memory seam + SQLite + memory tool |
| dsh-observe | OpenTelemetry and Langfuse observability exporter for DeepSeek Harness. |
| dsh-output-styles | Claude Code outputStyles-equivalent runtime style switching |
| dsh-permission-rules | Claude Code-style declarative allow/deny/ask permission rules with audit |
| dsh-plugin-certification | Community certification registry with repro-checkable grades and badges |
| dsh-plugin-doctor | Zero-dependency static + sandbox smoke detector for DSH plugins |
| dsh-plugin-guide | Plugin-development knowledge base as an on-demand agent skill |
| dsh-plugin-kit | Shared zero-runtime-dependency toolkit for the PerryLink DSH plugins |
| dsh-plugin-upgrade | One-package, one-corridor-index plugin upgrade skill: routes a repository to the matching closed corridor card |
| dsh-plugin-upgrade-015 | Merged 0.1.3-alpha.1 → 0.1.5-rc.1 upgrade corridor card plus a zero-dependency seam scanner |
| dsh-reach | Multi-channel approval/question bridge: WeChat/Telegram/Feishu, session console |
| dsh-research-report | Verifiable research-report engine: content-addressed evidence ledger and sealed versions |
| dsh-score | Multi-dimensional quality scoring for DeepSeek Harness plugins. |
| dsh-session-pin | Pin sessions in the Web sidebar with durable ordering |
| dsh-session-sync | Cross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store. |
| dsh-skill-pack-security | Security-audit skill pack: secret scan, dependency and supply-chain review |
| dsh-talk | Voice-first session loop for DeepSeek Harness: talk to it, hear it answer. |
| dsh-team-rooms | Cross-session team rooms: shared message bus, task board and timeline |
| dsh-test-drive | Isolated install-and-smoke test drives for DeepSeek Harness plugins. |
| dsh-ticktick | TickTick/Dida365 task bridge: session-header panel + 11 tools |
| dsh-translate | Vendor parameter translation and deterministic JSON repair for DeepSeek Harness. |
License
Apache License 2.0 © 2026 dsh-skill-pack-security contributors
从 DSH Desktop 市场安装
所有 PerryLink 插件均可在 DSH Desktop 内置市场中浏览:市场 → 来源 → 添加来源 → 粘贴 https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → 选中。安装仍需通过市场的 npm 身份校验与你的确认。
链接
同类插件
toby-bridges/api-relay-audit★ 862
从 DeepSeek Harness 对 AI API 中转站和 LLM 代理运行本地安全审计,生成 Markdown 报告,覆盖提示词注入、模型替换信号、工具调用改写、错误泄漏、流完整性和按 profile 启用的 Web3 风险。
SeaOf0/dsh-redteam-model★ 652
面向授权安全研究的 DSH 合集:九个工作模式(redteam 总控、渗透测试、代码审计、二进制分析、攻防评估、免杀对抗、应急溯源、云安全攻防、CTF 解题)与十五个运行时插件,设置页管理台支持一键部署、安装、更新与卸载。
howmp/dsh-pentest★ 566
面向 DeepSeek Harness 的授权渗透模式:以探索链路记录目标、线索、资产与漏洞,并在 Web 中可视化展示。
PerryLink/dsh-auto-review★ 218
审批链上的第二模型自动审查:只读审查子代理返回带理由的 allow/deny 结构化裁决,默认 fail-closed。
NanmiCoder/dsh-auto-mode★ 164
在 Workspace Write 与 Full access 之间增加 Auto 权限档:日常操作留在官方 workspace-write 沙箱内,由当前会话模型复核升权与破坏性调用,精确的越界访问按次放行一次,意图不明时询问,命中关键路径则拒绝。
PerryLink/dsh-permission-rules★ 117
Claude Code 风格的声明式权限规则:按序 allow/deny/ask 的 YAML 规则,在 tools/pre-execute 瀑布上匹配工具名、参数、工作区路径与 agent 身份,带完整会话日志审计、干跑模式与热重载。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。